[Samba] Fixed it myself... (ldap/winbind)

Josh Skains JSkains at deltad.com
Thu Jun 10 21:21:25 GMT 2004


You said:
--------------
Your thoughts - rely upon an assumption that is clearly false...that
ldap is usable without understanding it, that understanding it is
digestible in some easy form and that documentation doesn't exist.
--------------

I say:
--------------
First off, you are saying a lot that is "clearly false". LDAP can be used blindly in this case. All I needed is a way to avoid having winbind on system A from assigning UIDs on system B that is different. If the UIDs are not identical on all member unix servers, it screws up permissions on issues like NFS, which still has applications in my world.

I can toss water in a bucket without knowing how to chemically create the plastic.
--------------

You say:
--------------
I have posted this a few times the past 6 months but new users seem to
pop up without fully digesting the archives.
--------------

I say:
--------------
Sorry, but some of us have bosses and timeframes. Taking bits and peices of different cases, documents, and posts and trying to make them all fit isn't easy. I finally did it, and now it works fine. I also understand what I did and see that it isn't hard once you understand it, it's just a matter of "connecting the dots".

I have areas that you most likely aren't as good at.. You have areas that I most likely am not good at. If you came to me and asked me about one of my areas, I certainly won't be stomping around screaming the traditional "RTFM".
--------------

You say:
--------------
- LDAP is a learning curve all to it's own. It may be harder to learn
than any other that you have learned, certainly the concepts can be more
difficult to grasp than things like BIND, sendmail, apache.
--------------

I say:
--------------
Oh please. It isn't THAT complex, once you start to grasp it. Sure, I can see it getting more and more complex in larger applications, but sheesh, we are talking such a simple application here. My problem was just putting the different peices together.
--------------

You say:
--------------
- LDAP has no pat setup. There are a lot of LDAP providers (openldap,
sun, novell, etc.) and there are a number of different versions being
circulated, even by the same providers.
--------------

I say:
--------------
When someone comes in like me who doesn't have a need for LDAP in ANY OTHER application, then it does have a pat setup. You can say "our automated package only supports OpenLDAP. If you need LDAP for bigger things or want to use a different server, it is suggested you understand LDAP first and do the install manually".
--------------

You say:
--------------
- It makes little sense to use LDAP for Samba and not local system user
accounts, and why would you think that you can use LDAP for local
account security without fully digesting the implications and the
technology?
--------------

I say:
--------------
I don't need local accounts. I am using winbind. Did you even read my posts, or were you just too busy looking for someone to put down cause you are in a bad mood?
--------------

Whatever... Anyways....

JMS


More information about the samba mailing list